34 of 35 x402 Payment Hosts Lack Signed Offers, Developer Audit Finds
A developer running an AI-agent-facing x402 payment store audited all publicly listed x402 hosts on August 3, 2026, sending a single GET request to each. The results showed 34 out of 35 hosts did not serve a signed offer in their challenge header, while the one host that attempted signed offers returned malformed JWS tokens. The x402 protocol, revived by Coinbase and Cloudflare, includes a signed-offers extension that cryptographically commits sellers to their payment terms, but adoption remains minimal. The developer notes that implementing signed offers requires minimal effort, pointing to two lightweight open-source packages with no dependencies. A weekly public census of x402 host compliance has been launched, with results published and archived at scvd.store/corpus.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in